A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.
{
"github_reviewed": true,
"severity": "HIGH",
"github_reviewed_at": "2024-06-27T17:48:29Z",
"nvd_published_at": "2024-06-27T07:15:54Z",
"cwe_ids": [
"CWE-22"
]
}